Skip to main content

Port Details

Port
995
Transport
TCP
Service
POP3S
IANA service name
pop3s
Range
System port (0-1023)
Related ports

Security Exposure

POP3 servers accept mailbox passwords, so an internet-facing 995 listener is exposed to password guessing and credential reuse. Microsoft, which removed Basic authentication for POP and IMAP in Exchange Online, notes that Basic authentication makes credentials easier to capture and MFA harder to enforce.

Hardening

  • +Disable POP3 entirely if mail clients use IMAP or vendor protocols.
  • +Turn off cleartext POP3 on port 110 and support TLS 1.2 or later on 995, as RFC 8314 requires of mail access servers.
  • +Use modern authentication and MFA where the mail platform supports it.
  • +Rate-limit failed logins per account and per source address.

Monitoring

Log POP3 authentication failures and successful logins with source address, and alert on spray patterns across many accounts.

Tools for Auditing and Monitoring POP3S

Hydra

Open Source
Password Cracking

Parallelized network login auditing tool that tests dozens of remote authentication protocols including SSH, SMB, RDP, HTTP, and database services.

LicenseAGPL-3.0-only with OpenSSL exception
PlatformLinux, macOS, Windows, BSD, Solaris

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Wazuh

Free / Commercial
SIEM Tools

Open-source SIEM and XDR platform providing endpoint monitoring, log analysis, file integrity checks, and threat detection.

LicenseGPL-2.0-only with OpenSSL linking exception
PlatformLinux, Windows, macOS, Solaris, AIX, HP-UX

Frequently Asked Questions

What is the difference between port 110 and 995?→

Port 110 is plain POP3. Port 995 is POP3 over implicit TLS, registered as pop3s; RFC 8314 updated that registration.

Should POP3 be disabled?→

Where no clients need it, disabling it removes an authentication endpoint. If it is kept, RFC 8314 requires mail access servers to support TLS 1.2 or later and recommends deprecating cleartext access.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 995 is not guaranteed to be POP3S. Exploited-in-the-wild data from the CISA KEV catalog (CC0).